Centrally manage all security ingest connections from a single app.
Security Operations provides a unified interface to create, configure, and manage connections to third-party security products. Each connection establishes a dedicated ingest pipeline that routes security findings into the Dynatrace security.events Grail bucket via OpenPipeline.
It provides a single interface to:
| Integration | Category |
|---|---|
Alerts & detections | |
Code & build artifact scanners | |
Security posture | |
Code & build artifact scanners | |
Security posture | |
Alerts & detections | |
Generic |
Security Operations replaces the following standalone, push-based app integrations that are now deprecated:
If you have existing connections configured in any of these legacy apps, migrate them to
Security Operations and uninstall the legacy apps. See Migrate from legacy integrations.
With security findings ingested through
Security Operations, you can accomplish the following use cases.
To use
Security Operations, you need the following Dynatrace platform permissions.
| Action | Required permission |
|---|---|
View connections |
|
Create or modify connections |
|
Delete connections or manage sharing |
|
Query ingested data |
|
After creating the connection, the onboarding instructions guide you through the provider-side setup—for example, deploying a CloudFormation stack for AWS integrations or a Bicep template for Azure integrations.
You can also access
Security Operations directly via Settings > Collect and capture > Security data.
After completing provider-side setup, verify that data is flowing:
Security Operations, select the connection you want to verify.
Security Operations provides a central view of all your security integrations in one place, so you can assess the health and data flow of every connection without switching between individual integration screens.
From the main view, you can see:
Use this view to detect stalled or misconfigured integrations early and to confirm that provider-side changes (such as a rotated API key or a redeployed CloudFormation stack) have taken effect.
Security Operations, select the connection you want to edit.Deleting a connection removes the ingest pipeline and revokes the associated ingest token. Existing data in Grail is not affected.
Security Operations, select the connection you want to delete.Sharing controls who can view, use, or modify a connection. By default, only the connection owner has access.
To share a connection:
Security Operations, select the connection.Dashboards are available for discovery immediately after you create a connection. Deploy workflows before they run—no DQL knowledge or manual configuration is required.
Dashboards are automatically available as ready-made dashboards once a connection exists. Open
Dashboards and browse Ready-made dashboards, or access them directly from the connection detail view in
Security Operations.
| Dashboard | Description |
|---|---|
Audit logs | Audit log activity ingested from third-party platforms |
Container image alert reduction | Runtime contextualization of container findings for alert reduction |
Container scan events coverage | Coverage report for container image scan events |
Container vulnerability findings | Vulnerability findings in container image artifact registries |
Emerging threat intelligence reports | Newly reported threat intelligence, grouped by source and severity |
Host vulnerability findings reduction | Runtime contextualization of host findings for alert reduction |
Security findings | Overview of security findings reported across all connected products |
Security product coverage | Overview of security coverage across entities and environments |
Sign-in activity monitoring | Sign-in attempts, failures, and anomalies from ingested identity logs |
SonarQube posture overview | Code quality and security posture reported by SonarQube |
Threat exposure analysis | Correlates threat intelligence with observed logs and traces to gauge exposure |
Track remediation with vulnerability scans | Remediation progress measured across successive vulnerability scans |
Vulnerability findings | Overview of vulnerability findings reported across connected products |
Web network activity | Web and network request activity from ingested logs and traces |
Workflows automate the handling of incoming security findings. Unlike dashboards, workflows must be explicitly deployed before they run.
| Workflow | Description |
|---|---|
Email on new critical security findings | Sends an automated email notification whenever new critical-severity findings are ingested |
Jira ticket for critical container vulnerabilities | Files one Jira ticket per run for new critical container vulnerability findings |
Jira ticket for critical vulnerabilities | Files one Jira ticket per run for new critical vulnerability findings |
Slack notification for critical container vulnerabilities | Sends one grouped Slack digest for new critical container vulnerability findings |
Slack notification for critical vulnerabilities | Sends one grouped Slack digest for new critical vulnerability findings |
Not all templates are available for every integration. The templates shown in
Security Operations and in each app reflect only those that apply to your configured connections.
To deploy a Security Operations workflow template:
Workflows, select +Workflow.Alternatively, you can start deployment from the connection detail view in
Security Operations.
If you have connections configured in a legacy standalone app, migrate them to
Security Operations to benefit from centralized management, improved sharing controls, and future updates.
Security Operations includes step-by-step migration instructions for each legacy integration directly in the app.
To migrate:
Security Operations.